Skip to main content

Vendor archive

octobercms CVEs

Beta · best-effort

58 CVEs tagged to vendor octobercms5 Critical, 14 High, 32 Medium, 7 Low, 0 Unrated.

CVE-2026-25133

Published Apr 14, 2026

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the SVG sanitizatio…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25125

Published Apr 14, 2026

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings p…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24907

Published Apr 14, 2026

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the Event Log mail…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24906

Published Apr 14, 2026

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cross-Site Scripting (XSS) vulnerability in the Backend Editor…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22692

Published Apr 14, 2026

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vulnerability in the optional Twi…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-61676

Published Jan 10, 2026

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerabilities was identified in October CMS back…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61674

Published Jan 10, 2026

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerability was identified in October CMS backen…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51991

Published May 5, 2025

October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authenticated administrators with sites that have the `media.clea…

CVSS 1.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-45962

Published Oct 2, 2024

October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it c…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25837

Published Aug 16, 2024

A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload in…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25637

Published Jun 26, 2024

October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-24764

Published Jun 26, 2024

October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrators who may be redirected to an untrusted URL using the PageF…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-25365

Published Feb 8, 2024

Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-44382

Published Dec 1, 2023

October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`,…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-44381

Published Dec 1, 2023

October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`,…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44383

Published Nov 29, 2023

October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to the media manager that stores SVG files could create a sto…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43876

Published Sep 28, 2023

A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost f…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37692

Published Jul 26, 2023

An arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code via a crafted file.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-35944

Published Oct 13, 2022

October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations that rely on the safe mode rest…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24800

Published Jul 12, 2022

October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework. Prior to versions 1.0.476, 1.1.12, and 2.2.15, when the develop…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23655

Published Feb 24, 2022

Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not validate gateway server signatures. As a result non-authoritat…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21705

Published Feb 23, 2022

Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before rendering. An authenticated user wit…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32650

Published Jan 14, 2022

October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with access to the backe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32649

Published Jan 14, 2022

October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with "create, modify and…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41126

Published Oct 6, 2021

October is a Content Management System (CMS) and web platform built on the the Laravel PHP Framework. In affected versions administrator accounts which had previously been deleted…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 58 CVEsPage 1 of 3